Paramify Fedramp Jobs in Usa
28 positions found
What We’re Looking For
We’re building a team of enterprise hunters who thrive in complex sales. If you’re not used to outbound and owning your pipeline, this isn’t the role. We want closers who can:
- Prove a track record of exceeding quota, the cream always rises.
- Navigate enterprise complexity: multi-stakeholder deals, long procurement cycles, budget committees, and technical evaluations.
- Experience with RFPs, BPAs, and government procurement vehicles is a plus.
- Embrace the startup grind: we call it “working in dog years” you’ll get more exposure, more responsibility, and more growth than anywhere else.
- Be Field Corn, not a houseplant: resilient, resourceful, and able to grow in any conditions.
If you can already speak audit, infosec, or compliance frameworks (FedRAMP, CMMC, SOC 2), that’s a huge plus.
Responsibilities
- Own your funnel: Partner with marketing, collaborate with SDRs, and self-generate pipeline through outbound prospecting into target accounts.
- Run the full cycle: Discovery, product demos, executive alignment, technical deep dives, procurement navigation, and closing six-figure+ enterprise deals.
- Exceed your number: Drive ARR growth by consistently beating quota and building repeatable business within enterprise accounts.
- Sell to the top: Navigate C-suite, InfoSec leaders, and compliance teams. Teaching, tailoring, and taking control of the sale.
- Shape the org: As a core member of our sales team, help refine our playbooks, training, and culture. At Paramify, you don’t just carry a bag, you build the future.
Why Join Us
- Work at the intersection of compliance, security, and growth. The fastest-growing part of SaaS.
- Sell a product that changes how enterprises achieve compliance. Cutting audit prep from months to days.
- Join a team where performance is rewarded, voices are heard, and careers accelerate.
About Paramify
Paramify is the Iron Man suit for compliance and security teams helping GRC and InfoSec professionals work 1000x more efficiently in their documentation and audit prep. From SMB to Enterprise, manager to C-suite, our platform turns compliance into a growth enabler. We’re scaling fast with massive opportunities ahead in FedRAMP, GovRAMP, CMMC, and beyond.
Paramify is a special one, come help build it.
Driven by a unique Purpose, Culture, and Value Delivery Model, we enable meaningful connections between talented professionals and forward-thinking organizations.
Since our formation in 2002, organizations across commercial and public sectors have been trusting us to help build their teams with exceptional temporary and permanent talent.
Visit us at to learn more and view our open positions.
Please apply or call one of us to learn more For further inquiries regarding the following opportunity, please contact our Talent Specialist, Vijay Raj Jayachandran at (63 or Abdul at (224) 507-1295 Title: Systems Administrator Location: On-site at Austin, TX Duration: 12 Months Only W2 candidates are eligible for this position.
Third-party or C2C candidates will not be considered.
This position requires U.S.
Citizens only to meet the DoD requirements.
Description: This role is ideal for someone with approximately 5 years of hands-on experience in system administration, eager to expand their skills across a diverse technology stack and contribute to the stability and performance of our critical infrastructure.
As the primary Site IT Lead for our Austin office, you'll play a key role in maintaining our Commercial and FedRamp systems, supporting our users, and assisting in the implementation of new technologies.
Core Responsibilities: Advanced Troubleshooting and Technical Support: Be the main point of contact within the Austin office and travel to other sites as needed.
Serve as an escalation point for the global Service Desk Team providing advanced technical support to end-users for the various enterprise applications supported at client.
(e.g., Microsoft 365, Google Workspace, Jamf, Intune, Okta, Zoom, Slack, Github, etc) Collaboration and Coordination Collaborate with senior system administrators and other IT team members on business critical projects and initiatives Assist with driving the implementation of AI tools across the organization Coordinate with our InfoSec team to remediate security gaps or vulnerabilities across client's Enterprise Tools FedRAMP Serve as a primary point of contact for client's FedRAMP systems, collaborating closely with the Identity and Access Management team to uphold strict system compliance and ensure seamless business continuity.
Environment Ownership: Serve as the designated administrator for the FedRAMP boundary, managing a high-trust environment isolated from commercial production.
Asset Management and Documentation: Collaborate with the Service Desk Team to maintain an accurate inventory of all endpoints, documenting hardware and software details.
Assist with asset management, including tracking inventory of hardware and software.
Executive Support Providing premium and proactive technical assistance to client's senior leadership, executives, and their administrative staff in a fast-paced environment.
Serve as a primary point of contact fo rclient's executive assistant team.
Process Optimization: Identify, recommend, and implement continuous process improvements to enhance support operations and minimize incident occurrences.
Knowledge Base Development and Maintenance: Create and publish knowledge base articles for complex or novel issues lacking existing documentation.
Regularly update existing articles to ensure accuracy and relevance.
Troubleshoot AV systems as needed.
Assist in the management of AV Infrastructure Integrator visits and maintenance schedules.
Minimum Qualifications: Minimum of 5 years of work experience providing front-line IT support or systems administration work In-depth knowledge of Windows/Android, Apple ecosystem of products, including Macs, iPhones, and iPads Advanced proficiency with standard IT productivity tools and systems (e.g., Microsoft 365, Google Workspace, Jamf, InTune, Okta, Zoom, Slack).
Strong knowledge of IT security best practices and compliance standards.
Preferred Qualifications: Relevant industry certifications such as ITIL or CompTIA are considered a valuable asset.
Excellent troubleshooting skills and the ability to thoroughly resolve issues across various systems supported at client Excellent verbal and written communication skills that can work closely with both technical and management teams across the organization Excellent customer service skills and the ability to be a self starter Exposure to IT security best practices.
Experience with automation using no-code or low-code automation platforms such as Okta Workflows or Zapier About us: DivIHN, the 'IT Asset Performance Services' organization, provides Professional Consulting, Custom Projects, and Professional Resource Augmentation services to clients in the Mid-West and beyond.
The strategic characteristics of the organization are Standardization, Specialization, and Collaboration.
DivIHN is an equal opportunity employer.
DivIHN does not and shall not discriminate against any employee or qualified applicant on the basis of race, color, religion (creed), gender, gender expression, age, national origin (ancestry), disability, marital status, sexual orientation, or military status.
IT Support, microsoft 365, Apple, Windows/Android
Jr. ServiceNow Developer w/ Active Top Secret or DHS Clearance
Location: Hybrid in Ashburn, VA (must be onsite 2-3 days per week)
InDev is seeking a Jr. ServiceNow Developer to design, build, and enhance ServiceNow applications and integrations that support homeland security mission outcomes. You’ll work hands-on across ITSM and adjacent modules, develop high-quality scripts and flows, integrate with enterprise systems, and collaborate within an Agile team to deliver secure solutions aligned with DHS standards and FedRAMP requirements. This role will provide hands-on development for the government ServiceNow platform. This role also will ensure ServiceNow supports enterprise service delivery, governance, and modernization objectives, while aligning with the Technology Reference Model (TRM) and DHS enterprise IT standards. This position requires an active Top Secret clearance and/or active DHS clearance. Salary will be based on number of years of experience.
YOUR FUTURE DUTIES AND RESPONSIBILITIES
Development & Configuration
- Develop and configure ServiceNow modules (ITSM, ITOM, HR, GRC, etc.) to meet mission requirements.
- Build workflows, dashboards, catalog items, and integrations with enterprise systems.
- Implement automation and performance improvements across ServiceNow capabilities.
- Write clean, maintainable JavaScript using the Glide API (Business Rules, Script Includes, Client Scripts, Scheduled Jobs).
Integrations & Automation
- Implement integrations using REST/SOAP, MID Server, IntegrationHub, and scripted transforms.
- Automate workflows with Flow Designer and platform APIs; optimize performance and data quality.
Quality & Delivery
- Participate in grooming and refinement; estimate and deliver within Scrum sprints.
- Use ATF and unit tests; perform code reviews; manage update sets and basic CI/CD (e.g., Git branching, peer review, promotion workflows).
- Troubleshoot incidents/problems, perform defect resolution, and execute performance tuning.
Security, Compliance & Standards
- Follow platform secure coding practices; support FedRAMP, FISMA, and Section 508 considerations.
- Adhere to platform standards, naming conventions, and release governance; contribute to technical documentation and SOPs.
Stakeholder Collaboration
- Translate user stories into technical solutions; demo features in sprint reviews.
- Partner with BA/PM/architects to ensure traceability from requirements to delivered functionality.
- Collaborate with stakeholders, business analysts, and architects to translate requirements into ServiceNow solutions to include feature definition and creation and management of Jira epics and user stories.
QUALIFICATIONS
- Must hold an active Top Secret clearance and/or active DHS clearance.
- A Bachelor’s degree in Computer Science, Information Systems, Engineering, Business or other related discipline or a minimum of three (3) years relevant specialized experience.
- 3+ years of ServiceNow development experience
- CAD (Certified Application Developer - ServiceNow) certification required.
- Hands-on experience with JavaScript.
- Proven ability to design, configure, and implement complex ServiceNow modules, workflows, and business rules.
- Proven experience delivering projects using Agile methodologies.
- Hands-on experience with out-of-the-box ServiceNow features, such as workflows, scoped applications, and business roles.
- Proficient in cloud-based enterprise application platforms for IT services, operations, and business management.
- Strong communication skills to interact with technical teams and government stakeholders.
NICE TO HAVES
- Experience with DHS or CBP programs.
- Knowledge of enterprise governance, TRM processes, and AI/automation initiatives.
- Familiarity with Section 508, FISMA, and FedRAMP requirements.
Clearance: Must hold an active Top Secret clearance or DHS clearance.
WHY INDEV
- Innovative Environment: Join a team that thrives on creativity and innovation, where your ideas are not only heard but encouraged.
- Meaningful Impact: Contribute to projects that directly impact federal agencies, driving positive change on a national scale.
- Dynamic Collaboration: Work alongside diverse experts who are passionate about pushing boundaries and making a difference.
- Agile Mindset: Embrace Agile methodologies that encourage flexibility, adaptability, and rapid growth.
- Learning Culture: Enjoy ongoing learning opportunities and professional development to expand your skill set.
- Cutting-edge Tech: Engage with the latest technologies and tools in the data integration landscape.
If you’re ready to embark on a journey of innovation, collaboration, and impact, InDev welcomes you to join our team. Let’s shape the future together.
This is a critical role within our organization, responsible for taking primary ownership of infrastructure in a CMMC Level 2 certified environment designed to securely host Controlled Unclassified Information (CUI).
If you thrive in secure, compliance-focused environments and bring deep experience in defense, CMMC, FedRAMP, or similar regulatory frameworks, we want to hear from you.Key Responsibilities In this role, you will play a vital part in managing and maintaining our customer-facing IT infrastructure.
You will oversee the design, implementation, optimization, and security of systems to ensure reliability, performance, and compliance.
This role requires a proactive, security-first mindset and the initiative to drive continuous improvement across infrastructure, processes, and compliance controls.
Assist with design of long-term strategic vision for the IT environments.
Participate in product evaluations given by vendors for potential implementation.
Participate and provide expert guidance/response for all audits such as ISO27001, ISO9001, ISO 27701, CMMC, NIST etc.
Advise management on hosting budget for all infrastructure-related expenditures.
Design, deploy, and maintain the company's Hosting IT infrastructure, including servers, networks, storage, and virtualization environments.
Manage and monitor system performance, capacity, and availability to ensure optimal performance and uptime.
Implement and enforce security best practices to protect company and/or customer data and systems from potential threats and vulnerabilities.
Troubleshoot and resolve technical issues related to servers, networks, and applications in a timely manner.
Collaborate with other IT teams and departments to support business initiatives and projects.
Plan and execute system upgrades, patches, and migrations with minimal disruption to operations.
Design backup strategies for all systems.
Develop and maintain documentation, standard operating procedures, and policies related to system administration.
Mentor and provide oversight to other system administrators, sharing knowledge and best practices.
Serve as a point of escalation for other systems administrators.
Perform planning, configuration, deployment, and maintenance-work associated with the Flatirons Solutions production and development Hosting environments.
Perform systems administration tasks associated with implementation, migration and deployments utilizing remote hands.
Quickly and efficiently troubleshoot simple and complex issues to provide outstanding support for customer and internal needs.
Identify areas for process and efficiency improvement within systems operations; recommend solutions and assist in overseeing implementation.
Actively facilitate continuous improvement with a focus towards efficiency, value, and improved stability, security and privacy Ensure all necessary operational processes and procedures are carried out with a high level of attention to detail, expediency and on-time delivery.
Create and maintain system information diagrams and detailed documentation.
Monitor various systems capacity and provide analytics & forecasts for added or reduced capacity as required.
Use strong communication skills (both written and verbal) to direct with precision and clarity remote-hands technicians over the phone to execute deployment, break-fix, and upgrade plans accurately.
Understands and adheres to all requirements of the Integrated Management Systems (IMS), which includes Quality, Information Security, and Privacy.
Other duties as may be assigned.
Skills, Knowledge & Expertise Proficiency in virtualization technologies such as VMware or Hyper-V.
Strong understanding of networking principles and protocols (TCP/IP, DNS, DHCP, VLANs, etc.) Experience with cloud platforms such as AWS and Azure Familiarity with configuration management tools (e.g., Puppet, Chef, Ansible) Excellent problem-solving skills and the ability to troubleshoot complex technical issues.
Solid communication and interpersonal skills, with the ability to work effectively in a team environment.
Industry certifications such as MCSE, RHCE, CCNA, or AWS Certified SysOps Administrator preferred.
Experience with containerization technologies (Docker, Kubernetes) is a plus.
Knowledge of scripting languages (PowerShell, Bash, Python) for automation is a plus.
Experience with cybersecurity practices and tools preferred.
Preferred location is the Denver/Boulder area.
Driven by a unique Purpose, Culture, and Value Delivery Model, we enable meaningful connections between talented professionals and forward-thinking organizations.
Since our formation in 2002, organizations across commercial and public sectors have been trusting us to help build their teams with exceptional temporary and permanent talent.
Visit us at to learn more and view our open positions.
Please apply or call one of us to learn more For further inquiries regarding the following opportunity, please contact our Talent Specialist, Lavanya at (224) 369-0873 Title: Cybersecurity Specialist Duration: 6 Months with a strong possibility of extension or full-time Location: St.
Paul, MN or Abbott Park (North Chicago) Travel: Very limited, possibly 1 2 times during the 6 month period, likely none.
Work Schedule: 8 hours/day, 5 days/week Only W2 candidates are eligible for this position.
Third-party or C2C candidates will not be considered Role Overview The role has a strong focus on medical devices, IoT/sensor-based products, mobile applications, and backend systems, including building security standards, guidance, dashboards, and validating the effectiveness of cybersecurity controls.
Description: As a Senior Cyber Specialist Digital Enablement, you will play an important role in ensuring that Client product technologies leveraged by healthcare providers and consumers are secure-by-design.
These technologies range from regulated medical devices to e-commerce and customer loyalty solutions.
You will evaluate the cybersecurity posture of new and existing product technologies, identify risks, recommend mitigation strategies, and ensure timely remediation and closure.
You will bring deep expertise in security risks, controls, mitigations, and global cybersecurity standards to Client product teams.
This role is expert-driven and guidance-focused, requiring strong technical depth, excellent communication skills, and a proven ability to navigate a large, global environment.
You will partner closely with internal product owners, developers, engineers, security architects, and external collaborators to evaluate solutions, strengthen governance, and guide secure product development.
Your work will directly contribute to the delivery of scalable, compliant, and secure product technologies, cloud services, and connected applications.
The role focuses on consultative responsibilities rather than hands on development or cybersecurity operations.
Primary Responsibilities Develop and maintain security guidance documentation, including standards and frameworks Conduct full-stack architecture reviews of products and platforms, including consumer identity platforms Perform cybersecurity threat modeling and prepare outputs for review by internal and external stakeholders Establish, document, and monitor compliance with risk based and regulatory-informed cybersecurity requirements for individual products Collaborate with product designers and developers to ensure security considerations are integrated early into product design discussions Validate the security of product software supply chains and product deployment pipelines Develop risk mitigation strategies and recommend appropriate security controls Assess and prioritize product security risks through detailed evaluation of vulnerability assessments and penetration testing results Evaluate the effectiveness of product cybersecurity controls Identify and effectively communicate cyber risk trends Ensure risk management plans are clearly documented, actionable, and accurately reflect the organization's risk tolerance Track and ensure product compliance with defined vulnerability remediation SLAs.
Participate in governance forums, architecture reviews, and technical discussions as a representative of Product Cybersecurity Required: At least 5 years of experience but typically 7 plus years of experience is required.
Possess expertise in valuing and implementing industry standards such as the ISO 27001/2, SOC 2, HITRUST and FedRAMP Information Security standard and the ISO 22301 Business Continuity Standard.
Experience with implementation and operational use of GRC toolsets (Governance Risk and Compliance).
Possess CISSP certification (or similar) and be knowledge of national and international regulatory compliances and frameworks such as ISO, SOX, BASEL II, EU DPD, HIPAA, and PCI DSS.
Ability to influence policy/standards for emerging tech (AI, quantum, cloud).
About You 7 years of experience in cybersecurity or technology architecture, assessment, or consulting with a focus on the development of secure digital product technologies Experience conducting risk assessments, control assessments, and governance reporting Ability to clearly articulate cybersecurity risks and recommended mitigations to product development teams Strong understanding of modern technology stacks, including cloud native architectures and API-driven services Understanding of core concepts related to identity and access management, secure software development, network security, and cryptography Familiar with device to device, service to service, and consumer identity and access management practices Familiarity with modern phishing-resistant authentication technologies, including WebAuthn and Passkeys Understanding of cybersecurity risks associated with emerging technologies, including quantum computing and artificial intelligence Knowledge of global medical device regulatory frameworks Excellent analytical, problem-solving, and communication skills Working knowledge of security frameworks and standards (e.g., NIST, ISO/IEC 27001, PCI DSS) Strong collaboration and influencing skills, with the ability to work effectively across technical and business teams Exceptional written and verbal communication skills, with the ability to tailor complex information for diverse audiences Strong analytical and problem solving skills, with the ability to work independently and manage multiple priorities Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Software Engineering, or a related field but not mandatory if experience is strong Preferred Qualifications Strong preference for candidates with cybersecurity experience across e commerce, mobile apps, IoT, or medical devices.
Preferred certifications include CISSP, HCISPP, CISM, CCSP, SABSA Foundation, CISA, or similar industry-recognized certifications Background in application security, product security, and secure development practices.
Experience supporting mobile applications, sensors, and backend operational systems.
Ability to draft, influence, and operationalize cybersecurity policies and standards.
Reading Static Application Security Testing (SAST)/Dynamic Application Security Testing (DAST) outputs, pen test results; collaborating with teams; no major required internal tools.
Top 3 required skills: Cybersecurity consulting w/ development teams (software/hardware).
Ability to influence policy/standards for emerging tech (AI, quantum, cloud).
Ability to evaluate the effectiveness of cybersecurity controls.
Top 3 preferred skills: Medical device or IoT cybersecurity; development background; broader product security experience.
Certifications: Not required; experience is prioritized over certs.
Industry experience: Medical device preferred; e commerce, IoT, cloud, and mobile app security also acceptable.
Systems used daily: Reading Static Application Security Testing (SAST)/Dynamic Application Security Testing (DAST) outputs, pen test results; collaborating with teams; no major required internal tools.
Personality traits: Curious, detail oriented, collaborative, strong communication, relationship builder.
Interview Process: One Teams Video interview About us: DivIHN, the 'IT Asset Performance Services' organization, provides Professional Consulting, Custom Projects, and Professional Resource Augmentation services to clients in the Mid-West and beyond.
The strategic characteristics of the organization are Standardization, Specialization, and Collaboration.
DivIHN is an equal opportunity employer.
DivIHN does not and shall not discriminate against any employee or qualified applicant on the basis of race, color, religion (creed), gender, gender expression, age, national origin (ancestry), disability, marital status, sexual orientation, or military status.
SOX, ISO, HIPAA, HITRUST, SOC 2, ISO 27001/2, BASEL II, EU DPD
L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs always in mind, our employees deliver end-to-end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security.
Job Title: Specialist, Software Engineering (Service Reliability Engineer)
Job Code: 33584
Job Location: Melbourne, FL or Chantilly, VA (on-site)
Job Schedule: Rotational shifts 24x7
Job Description:
L3Harris is seeking an experienced Software Engineer to join our dynamic team, focusing on operating, maintaining, and sustaining a Cloud-based 24x7 operational system. The role encompasses the live monitoring and real-time anomaly troubleshooting of Cloud data operations, and participating in the sustainment development efforts (patching, upgrades) for that environment, using an agile development process.
Essential Functions:
* Develop, maintain, and enhance cloud applications using Python, Typescript and Java
* Provide 24x7 real time monitoring and troubleshooting of an operational Cloud based Data Operations system (Shift work; nights and weekends as required on a rotational schedule).
* Shifts to include: First Shift Day (06:00am - 2:30pm EST), 2nd Shift Evening 10% differential (2:00pm - 10:30pm EST), 3rd Sift Night 12% differential (10:00pm - 06:30am EST).
* First line anomaly lead: reporting/resolving/future mitigation of any issues encountered.
* Collaborate with cross-functional teams to define and implement engineering changes (enhancements, automation, capability improvements and bug fixes)
* Develop and maintain technical documentation related to Cloud sustainment and operations.
* Organize and support training sessions for operations personnel as required.
* Ensure compliance with NIST, Department of Commerce and NOAA IT security standards such as FISMA, FedRAMP, and NIST 800.53
* Develop, maintain, and enhance cloud applications using Python, Typescript and Java.
* Ability to obtain and maintain a Public Trust.
* Tool familiarity: Grafana, Prometheus, influx DB, Postgres, CDK (Cloud Development Kit), Cloud formation, Ansible, GIT (Global Information Tracker), Active Directory, Networking, GRE (Global Accelerator Resolvers & Endpoints), EKS (Elastic Kubernetes Service), RDS (Relational Database Service), Lambda, IAM (Identity and Access Management)
Qualifications:
* Bachelor's Degree and a minimum of 4 years of prior related experience. Graduate Degree or equivalent with 2 years of prior related experience. In lieu of a degree, minimum of 8 years of prior related experience.
* Experience with commercial cloud systems (Cloud Linux SYS Admin/coding) and services (AWS, Azure, etc.).
* Experience with any of the following tools: Grafana, Prometheus, influxdb, Postgres, CDK (Cloud Development Kit), Cloud formation, Ansible, GIT (Global Information Tracker), Active Directory, Networking, GRE (Global Accelerator Resolvers & Endpoints), EKS (Elastic Kubernetes Service), RDS (Relational Database Service), Lambda, IAM (Identity and Access Management).
Preferred Additional Skills:
* Experience with Agile software development best practices and tools (SAFe, Jira, Git, etc.) and participation in continuous Agile planning and coordination.
* Experience with containerization technologies (Docker, Kubernetes).
* Familiarity with container observability tools (Prometheus, Grafana, InfluxDB, PromQL).
* Background in security architecture and secure coding practices.
* Experience in domain-driven design (DDD) and API-first development.
#LI-KB1
L3Harris Technologies is proud to be an Equal Opportunity Employer. L3Harris is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws. L3Harris maintains a drug-free workplace and performs pre-employment substance abuse testing and background checks, where permitted by law.
Please be aware many of our positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information.
By submitting your resume for this position, you understand and agree that L3Harris Technologies may share your resume, as well as any other related personal information or documentation you provide, with its subsidiaries and affiliated companies for the purpose of considering you for other available positions.
L3Harris Technologies is an E-Verify Employer. Please click here for the E-Verify Poster in English or Spanish. For information regarding your Right To Work, please click here for English or Spanish.
Business Area:
EngineeringSeniority Level:
Mid-Senior levelJob Description:
At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry. Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world's largest enterprises.
The Product Security group ensures our platforms are secure by design and compliant with the world's most rigorous industry and government standards. As a Staff Product Security Engineer, you will serve as a technical architect of trust and the primary connective tissue between Security, Product, and Engineering teams. You will be responsible for translating complex global security requirements into actionable, automated engineering solutions, acting as the "go-to" expert for the Security Features team.
As a senior technical member of the team, you will exercise significant latitude in defining technical objectives and architectural approaches to complex challenges. Leveraging a deep understanding of distributed systems and cloud-native platforms, you will lead high-impact, security-driven initiatives across the entire Cloudera product suite.
As a Staff Software Engineer, you will:
Architect and maintain advanced build tooling to automate and accelerate vulnerability remediation across all engineering pillars.
Lead Proof of Concepts (POCs) and evaluate third-party security tools to enhance our security posture without compromising developer velocity.
Design and develop core security features, including FIPS compliance, TLS/Encryption, Secrets Rotation, Identity & Access Management (IAM), and Certificate Management.
Drive root-cause analysis and triage for complex, product-wide stability issues related to security infrastructure.
Engineer specialized observability tools, such as encryption inventories, to audit and measure security standards during feature delivery.
Author comprehensive design specifications and test plans for cross-component security features, providing technical clarity in the face of ambiguity.
Elevate the team's technical bar through high-quality code reviews, documentation standards, and active mentorship of engineering talent.
Partner across organizational lines, collaborating with internal stakeholders and senior management to resolve customer escalations and align with long-term objectives.
We're excited about you if you have (Required Qualifications):
Bachelor's degree in Computer Science or a related field (or equivalent experience) with 6+ years of professional software engineering experience.
Deep technical expertise in containerized environments, specifically Kubernetes (EKS) and Docker.
Strong command of general-purpose and scripting languages, including Java, Python, Go, and Bash.
Proven experience with Infrastructure-as-Code (IaC) tools such as Terraform and Helm to automate secure infrastructure rollouts.
Expert-level experience automating complex CI/CD pipelines using platforms such as GitLab CI/CD, Jenkins, or GitHub Actions.
Exceptional troubleshooting skills with a track record of identifying root causes for site outages and resolving P1 escalations.
You may also have (Preferred Qualifications):
Experience with Post-Quantum Cryptography to support upcoming product transitions.
Practical experience with FIPS 140-3, TLS 1.3, and modern encryption standards.
Proven ability to automate CVE remediation and integrate SAST/DAST scanning tools-such as Trivy, Aquasec, Tenable, or Fortify-into developer workflows.
Familiarity with government compliance frameworks and industry standards including FedRAMP, ISO 27001, and SOC 2.
Deep understanding of secure coding practices and common vulnerabilities as outlined in the OWASP Top 10.
Experience working with Identity and Access Management (IAM) or Identity Governance platforms.
Strong management skills with a demonstrated ability to influence cross-functional teams and drive results in a remote environment.
This role is not eligible for immigration sponsorship
What you can expect from us:
Generous PTO Policy
Support work life balance with Unplugged Days
Flexible WFH Policy
Mental & Physical Wellness programs
Phone and Internet Reimbursement program
Access to Continued Career Development
Comprehensive Benefits and Competitive Packages
Paid Volunteer Time
Employee Resource Groups
EEO/VEVRAA
#LI-BV1
#LI-REMOTE
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.
We are looking for a Firewall Administrator to join our team in support of a program with our DoD customer.
Responsibilities Include:
- Plan and deploy Enclave Boundary Defense systems and programs including firewall, proxy server, cloud services and other devices and applications.
- Plan and deploy De-Militarized Zones (DMZs) for each managed firewall as required.
- Provide onsite and remote support to boundary security and programs, which include Checkpoint Firewalls, Aviatrix Product Suite, various types of cloud security, security controls and any other platforms.
- Participate in the development, testing, and implementation of firewalls and proxy servers
- Verify devices are configured in accordance with DISA Security Technical Implementation Guides (STIGs).
- Product lifecycle management and upgrades to include installation of hotfixes, patches, and any other features to improve product performance.
- Evaluate and recommend firewall solutions for technology refreshes.
- Deploy and sustain new firewall solutions as prescribed by the government.
- Coordinate with Tier III support teams and government customers throughout design, planning, implementation, and sustainment phases.
- Research and provide quotes and documents necessary to renew licenses and equipment maintenance for firewall, proxy and cloud services.
- Maintain all current applicable firewall, proxy appliance and cloud services policies to include DoD. Participate in the development, implementation, and maintenance of a secure and effective means of remote access for employees who are working offsite.
- Develop and deliver briefings to the upper-level management as required on a variety of subjects relating to Enclave Boundary Defense.
- Provide firewall troubleshooting (24x7x365 on-call support).
- Review and resolve automated firewall log issues as to threats or possible compromises.
- Provide daily maintenance and support for all Enterprise Boundary Defense systems including monitoring system and log files.
- Review and resolve automated firewall log issues as to threats or possible compromises.
- Notify appropriate personnel of possible threats or systems vulnerabilities.
- Respond appropriately to reported or identified incidents in accordance with the Incident response plan.
- CSP Security Posture Assessment: Conduct comprehensive security assessments of existing and planned CSP deployments, identifying vulnerabilities and recommending remediation actions aligned with industry best practices and relevant security frameworks (e.g., NIST CSF, CIS and Benchmarks).
- Security Architecture Documentation, Design and Implementation: Document, design, implement, and maintain secure network architectures for CSP environments, including secure connectivity, network segmentation, intrusion detection/prevention systems (IDS/IPS), and data loss prevention (DLP) solutions. Maintaining comprehensive documentation of security controls, configurations, and processes within the CSP environment.
- Cloud Security Operations and Monitoring: Provide continuous security monitoring and incident response capabilities for CSP environments, including log analysis, threat intelligence integration, vulnerability management, and incident response planning and execution.
- Audit, Compliance and Governance: Ensure compliance with relevant security regulations and standards (e.g., FedRAMP, FISMA, NIST) for CSP environments, including documentation, reporting, and audit support. Cooperating fully with authorized Government audits and assessments of the CSP environment, providing timely access to documentation, systems, and personnel. Follow DoD Cloud Computing Security Requirements Guide (SRG) and other applicable DoD issuances and instructions.
- Training and Knowledge Transfer: Provide training and knowledge transfer to Government personnel on best practices for securing CSP environments, covering topics such as cloud security fundamentals, secure configuration, threat detection and response, and incident management.
Required Skills, Qualifications and Experience:
Minimum Experience:
- Five (5) years of relevant experience to include the following:
- Working knowledge of Firewalls.
- Working knowledge and understanding of industry standard network environments to include firewall and security hardware/software.
- Working knowledge of Information Assurance Best Practices.
- In depth knowledge of LAN and WAN operations.
- Knowledge of industry standard Incident Ticket Tracking systems for inputting incident tickets and creating work orders.
- Comprehensive knowledge of DOD and DLA security regulations, guidelines, and policies, to include, but not limited to, IA standards.
- Working knowledge of the installation, configuration and day-to- day sustainment of network equipment, to include but not limited to firewalls and other network appliances.
Security Clearance:
- Sensitivity Level: Must possess IT-I Critical Sensitive security clearance or have a current National Agency Check with Local Agency Check and Credit Check (NACLC) at time of proposal submission.
- Clearance: DoD Secret
Certifications:
- IAT Level II certification or higher (one of the following): CCNA Security, CySA+, GICSP, GSEC, Security+CE, CND, SSCP, CASP+ CE CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
- Computing Environment (one of the following): CCSA, CCSE or CCSM
Location:
- Candidates must reside within a commutable distance of one of the following locations in order to work onsite full time: Columbus, OH; Fort Belvoir, VA; or New Cumberland, PA.
Preferred Qualifications:
- One of the following: AWS Cloud Practitioner, Microsoft Certified: Azure Fundamentals, or Comp TIA Cloud+
Work Environment and Physical Demand:
- Must be able to lift up 50 lbs.
At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.
- 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
- Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
- 401(k) with Match: We match 3% of your contributions with immediate vesting.
- Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
- Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
- Parental Leave: 15 days of fully paid leave for new parents, because family matters.
- Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving.
- Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
- Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.
At AGE, you'll do work that matters, supported by a company that delivers for its people.
DevOps Engineer
Job ID
2026-2165
# of Openings
1
Category
Software Engineering
Overview
Pyramid Systems is seeking an experienced DevOps/AWS Engineer take responsibility for creating, building, deploying, orchestrating, and automating deployment packages in AWS cloud-based environment.
Responsibilities
- Design and automate cloud environments at scale using Infrastructure as Code tools
- Design and develop fully automated software delivery pipelines
- Efficiently collaborate within and across agile teams to maximize productivity
- Develop technical documentation, architecture diagrams, and similar
- Engage in all agile ceremonies including backlog grooming, demos and retrospectives
- Eliminate roadblocks and hindrances preventing teams from delivering software
- Assist the team in documenting and leveraging cloud and DevOps best practices
- Fullstack development using modern frameworks and languages Python or JavaScript
- Quickly learn and adapt to new technologies, frameworks, or project requirements as needed
- Apply critical thinking and a solutionoriented mindset to identify issues and propose effective resolutions
- Integrate AI/ML models into applications to enhance functionality, automation, and overall user experience
- Collaborate with crossfunctional teams to design scalable architectures supporting both traditional and AIdriven features
- Implement best practices for model deployment, data handling, and performance optimization in AIenabled systems
Qualifications
- Bachelor's degree in computer science, engineering, or related field
- Must have AWS certs and/or CompTIA relevant certifications
- 5+ years of experience managing cloud or virtualized infrastructure
- Passionately practices Infrastructure automation using Terraform, Ansible, or similar
- Knowledge and familiarity with Docker and Kubernetes
- Fluent in at least one programming language - Python, Go, Typescript, JavaScript or similar
- Strong system administration experience in Linux
- Knowledge of AWS DevOps with GitHub Actions, GitLab CI/CD, Jenkins, or similar
- Strong team player, communicates well, and caries an infectious can-do attitude
- Must have hands on experience with Claude Code or similar AI tools
- Strong experience in compliance frame works like: ATO, SOC 2, PCI-DSS, FedRAMP, NIST 800-53, or CIS Benchmarks
Target Pay Range
The below listed pay range for this position is not a guarantee of compensation or salary. The final offered salary will be influenced by a host of factors including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at Pyramid Systems that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits, to include our Employee Stock Ownership Program, FlexPTO, and learning and development opportunities.
Pyramid Min
USD $123,760.00/Yr.
Pyramid Max
USD $185,640.00/Yr.
Why Pyramid?
Pyramid Systems, Inc. is an award-winning, technology leader, driving digital transformation across federal agencies. We empower forward-thinking innovations, accelerate production-ready software, and deliver secure solutions so federal agencies can meet their mission goals. Voted a Top Workplace, both regionally (Washington, DC) and Nationally (USA) the past 2 years (2023 and 2024) based on the feedback from our employees, we are headquartered in Fairfax, VA. and have a growing national footprint. We value and promote our Flexible Workplace approach because of the positive impacts it has on work-life integration. We remain committed to ensuring every employee's voice is heard, performance and results are recognized and rewarded, development and advancement is a focus, and diversity, equity and inclusion is a company priority. We offer competitive compensation and benefits (including a recently launched Employee Stock Ownership Plan - ESOP), a robust performance-based rewards program, and we know how to have fun! Our people and culture have endured and delivered for our clients for nearly three decades.
EEO Statement
Pyramid Systems, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
Clinical Program Manager - Essex Management
Remote in US except, if in Maryland, DC, VA & Delaware; must be comfortable in being on client site at least once a week.
This position supports "Essex, an Emmes Company". Essex is a biomedical informatics and health information technology-focused consultancy founded in 2009 and headquartered in Rockville, MD. The Essex team comprises experts with extensive experience in strategically developing and managing complex health and biomedical information programs for clients in the Federal Government, research academia, and private sectors.
Emmes Group: Building a better future for us all.
Emmes Group is transforming the future of clinical research, bringing the promise of new medical discovery closer within reach for patients. Emmes Group was founded as Emmes more than 47 years ago, becoming one of the primary clinical research providers to the US government before expanding into public-private partnerships and commercial biopharma. Emmes has built industry leading capabilities in cell and gene therapy, vaccines and infectious diseases, ophthalmology, rare diseases, and neuroscience.
We believe the work we do will have a direct impact on patients' lives and act accordingly. We strive to build a collaborative culture at the intersection of being a performance and people driven company. We're looking for talented professionals eager to help advance clinical research as we work to embed innovation into the fabric of our company. If you share our motivations and passion in research, come join us!
Primary Purpose
We are seeking a highimpact, strategic, and executionoriented directorlevel Program Manager to lead and mature the organization's program strategy, delivery excellence, and client enablement capabilities. This role provides both strategic leadership and handson management, including direct oversight of staff and responsibility for career development, coaching, and performance management.
This role will shape how internal departmental initiatives and client programs are planned, governed, staffed, measured, and communicated, ensuring delivery rigor while enabling flexibility and innovation across diverse client environments.
This role works in close partnership with portfolio, engineering, bioinformatics, data science, and business development leadership to ensure integrated delivery, effective resource utilization, proactive risk management, and an exceptional client experience.
The ideal candidate is a decisive people leader and systems thinker who thrives in complex and evolving environments, balances strategy with execution, and brings a strong client first mindset. Success requires the ability to influence at the executive level, mature organizational capabilities, and cultivate a collaborative, empowered team culture that supports excellence in deliveryfirst mindset. Success requires the ability to influence at the executive level, mature organizational capabilities, and cultivate a collaborative, empowered team culture that supports excellence in delivery.
Responsibilities
- Establish and execute departmental goals and objectives aligned to enterprise strategy, contract priorities, and client mission outcomes; define and monitor KPIs to drive accountability and data-informed decision-making.
- Design, implement, and continuously mature program management, governance, and delivery enablement frameworks that scale across portfolios while ensuring compliance with federal, regulatory, and organizational standards.
- Provide executive-level visibility into portfolio, program, and project health through standardized dashboards, metrics, and reporting-enabling proactive management of risks, issues, dependencies, and performance trends.
- Partner with portfolio and divisional leadership to support investment prioritization, funding decisions, and resource allocation, balancing client commitments, growth objectives, and staff sustainability.
- Ensure full lifecycle contract execution excellence, including initiation, execution, closeout, client reporting, lessons learned, and continuous improvement integration.
- Lead people management strategy for the department, including performance management, career development, succession planning, training pathways, and promotion readiness.
- Own departmental workforce and strategic resource planning, including forecasting, recruitment, onboarding, capacity planning, skills development, and certification alignment.
- Ensure compliance with staff allocations plans, time reporting, and internal policies across billable, internal, and strategic initiatives.
- Actively support business development efforts, including RFP solutioning, staffing models, transition planning, delivery onboarding, and ongoing executive client engagement.
- Champion quality-by-design principles across all delivery artifacts and processes; oversee SOP evolution, process training, internal audits, and continuous improvement initiatives.
- Maintain strong awareness of industry, regulatory, and technology trends; represent the organization through thought leadership, publications, conferences, and strategic forums.
Required Skills:
- Advanced expertise in program, portfolio, and PMO leadership, including framework design, governance models, and delivery maturity assessments (e.g., PMI, PMO, Agile/Hybrid environments).
- Strong command of program operations, including financial management, forecasting, risk and issue management, resource optimization, and executive reporting.
- Demonstrated experience leading complex life sciences and health IT programs supporting clinical research, bioinformatics, public health, biomedical informatics, and regulated data environments.
- Exceptional communication and executive presence, with the ability to influence senior leaders, advise clients, and align cross-functional teams around shared outcomes.
- Proven problem-solving and systems-thinking capabilities, with a track record of driving process improvement, operational scalability, and organizational maturity.
- Ability to rapidly assess priorities, adapt to evolving client environments, and translate strategy into executable roadmaps.
- Strong regulatory and compliance knowledge, including clinical research regulations, healthcare privacy, and federal IT compliance standards (e.g., FDA, 21 CFR Part 11, HIPAA, FISMA, FedRAMP, CMMI, ISO).
- Experience operating in federal health environments (e.g., HHS, NIH, NCI), with familiarity across consulting delivery models, contract vehicles, and business development lifecycle.
Required Areas of Focus:
Program Management Leadership
- Own and evolve client-facing program and project roadmaps, ensuring alignment with mission goals, regulatory requirements, funding constraints, and delivery capacity
- Contribute to standardized BD-to-Delivery transition processes, ensuring early engagement, clarity of scope, staffing, budgets, timelines, and accountability prior to execution.
- Ensure consistent contract execution through disciplined tracking of deliverables, milestones, financials, and performance metrics, including CPAR inputs and self-assessments.
- Design, maintain, and continuously improve enterprise delivery dashboards, providing visibility into:
- Program and project health summary
- Resource utilization and capacity
- Budget performance and forecasting
- Risk and issue trends
- Key milestones and outcomes
Contract performance and quality metrics
- Establish and enforce a structured reporting cadence to support proactive leadership engagement and timely decision-making:
- Weekly: Project and program status
- Monthly: Portfolio performance and financial reviews
- Quarterly: Strategic outlook, risk posture, and growth alignment
- Serve as a senior client relationship leader, cultivating trusted partnerships and proactively identifying opportunities to enhance delivery value and expand engagements.
Financial & Resource Management
- Partner with leadership teams to define, manage, and optimize portfolio, program, and project-level budgets.
- Develop and maintain a comprehensive resource capability matrix capturing skills, certifications, experience, performance insights, and availability.
- Optimize workforce utilization by aligning staffing decisions with delivery needs, staff development goals, and long-term organizational strategy.
- Lead and support staff transitions, onboarding, promotions, and role changes with minimal delivery disruption.
- Drive training and capability development strategies aligned to SOPs, industry standards, and evolving client needs.
Stakeholder Engagement & Communication
- Act as a senior liaison between executive leadership, program teams, and client stakeholders.
- Strengthen client partnerships through structured feedback mechanisms, contract / project performance reviews, and strategic planning engagements to support change agility and account growth.
- Enable cross-division collaboration to ensure integrated delivery and shared accountability.
- Communicate performance, risks, and opportunities through clear dashboards, briefings, and executive presentations.
Advisory & Consultation
- Provide strategic advisory services to internal and external stakeholders navigating complex program and project and delivery challenges.
- Translate technical, business domain, and operational concepts into actionable strategies that enable informed decision-making.
- Serve as a trusted advisor supporting both delivery excellence and organizational growth.
Qualifications
- Education: Bachelor's degree required; Master's degree in a scientific, health, or program management discipline preferred. PMP or equivalent certification desired.
- Experience: Minimum of 10 years in senior program strategy and delivery leadership roles across federal, academic, and private-sector environments.
- Program Leadership: Extensive experience program management, PMO leadership, governance, financial management, and large-scale delivery enablement.
- Industry Knowledge: Strong background in life sciences, clinical research, bioinformatics, health informatics, and public health.
- Leadership & Business Acumen: Proven ability to lead distributed teams, manage complex stakeholder environments, and influence at the executive level.
- Business Development: Demonstrated success supporting client growth, solution design, and consulting delivery models.
- Federal Health IT Experience: Experience supporting HHS, NIH, NCI, or similar agencies strongly preferred.
Why work at Emmes?
At Emmes, your actions and hard work will have a direct impact on public health initiatives, both globally and in our local communities with opportunities for volunteerism through our Emmes Cares community engagement program. We offer a competitive benefits package focused on the health and needs of our growing workforce, including:
- Flexible Approved Time Off
- Tuition Reimbursement
- 401k Retirement Plan
- Work From Home Anywhere in the US
- Maternal/Paternal Leave
- Casual Dress Code & Work Environment
CONNECT WITH US!
Follow us on Twitter - @EmmesCRO
Find us on LinkedIn - Emmes
The Emmes Company, LLC is an equal opportunity employer and does not discriminate in its selection and employment practices. All qualified applicants will receive consideration for employment without regard to disability or protected veteran status.
#LI-Remote
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.
We are looking for a Cloud Computing Specialist (CCS) to join our team in support of a DoD customer in Alexandria, VA. The CCS will serve as an Information Assurance and Cloud Computing SME with regards to Certification and Accreditation (C&A) and a broad coverage of the application of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) standards and guidance as outlined in the NIST Special Publication(s) (SP) 800-53 and 800-37 (current versions).
Responsibilities Include:
- Provide full lifecycle Information Assurance (IA) support for systems maintaining current Authority to Operate (ATO) under RMF via eMASS.
- Update, maintain, and validate RMF artifacts, IA documentation, scorecards, and accreditation packages.
- Develop, manage, and execute POA&M, MOUs/MOAs, risk acceptance documentation, and other compliance artifacts.
- Ensure continuous compliance with DoD/DLA RMF requirements supporting ATO and Authority to Connect (ATC).
- Support RMF Assessment & Authorization (A&A) processes and validate eMASS inputs.
- Conduct annual risk assessments and IA control validations.
- Review engineering projects and change requests to ensure implementation of required IA controls and policies.
- Support connection approval processes and manage required documentation.
- Identify security risks and enhancements; develop and track mitigation strategies.
- Evaluate and recommend security components and configurations (e.g., firewalls, IDS/IPS).
- Provide IA input to Technical Review Boards (TRB) and Change Control Boards (CCB).
- Support DLA CERT, network engineering, and NTS teams on IA compliance and security event response.
- Maintain situational awareness of USCYBERCOM alerts/advisories and assess operational impact.
- Analyze proposed IT acquisitions for IA, interoperability, architecture, and standards compliance; identify required security configuration guidance.
- Support DISN sub-network accreditation to achieve/maintain full ATO and ATC.
- Plan and execute IA requirements for technology migrations affecting accredited systems.
- Implement and maintain information protection guidance for controlled unclassified and classified information in accordance with DoD/DLA policy.
Required Skills, Qualifications and Experience:
- Minimum Requirement:
- Five (5) years of relevant C&A experience; Risk Management Framework (RMF) and NIST C&A experience
- DOD IA experience.
- Certification Requirements:
- Cloud Computing Security Certification
- Certification meeting DOD 8570.01 IAM III (CISSP, CISM, etc.)
- Skills and Experience:
- Experience in assessing IA Controls and conducting C&A reviews for large, complex Information systems.
- Ability to work independently with substantial cloud computing security knowledge.
- Must have the essential skillsets to identify, manage and resolve cloud computing security risk and implement "best practices" as applied within a cloud environment (across all of the different deployment and service models, and derivatives).
- Must be well versed in FedRAMP assessment methodology of security and privacy controls deployed in cloud information systems to include six (6) domain areas. The six domains include: Architectural Concepts & Design Requirements, Cloud Data Security, Cloud Platform & Infrastructure Security, Cloud Application Security, Operations, Legal & Compliance.
- Clearance Requirement:
- This position requires a SECRET with a Tier 3 investigation.
Compensation: $100,000+
At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.
- 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
- Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
- 401(k) with Match: We match 3% of your contributions with immediate vesting.
- Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
- Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
- Parental Leave: 15 days of fully paid leave for new parents, because family matters.
- Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving.
- Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
- Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.
At AGE, you'll do work that matters, supported by a company that delivers for its people.
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.
We are looking for a Team Lead Firewall Administrator to join our team in support of a program with a DoD customer.
Responsibilities Include:
- Provide overall supervision for vendor employees to include, but not limited to, planning, and managing the project professionally, ensuring that work is scheduled properly to obtain maximum use of resources; ensuring that accurate and timely reports are provided.
- Resolve problems, allocate resources, manage personnel, and monitor operation performance taking direction from the government to ensure complete satisfaction.
- Under general supervision, develop the requirements of a product from inception to conclusion.
- Develop required specifications for simple to moderately complex problems.
- Coordinate with the Vendor PM, TPOCs, and government user representatives to ensure accurate solutions and user satisfaction on technical matters.
- Provide input to the PM on the schedule, weekly and monthly reports, transition plan, 8570/8140 reports, IPR briefings, and kick-off meeting.
- Plan and deploy Enclave Boundary Defense systems and programs including firewall, proxy server, cloud services and other devices and applications.
- Plan and deploy De-Militarized Zones (DMZs) for each managed firewall as required.
- Provide onsite and remote support to boundary security and programs, which include Checkpoint Firewalls, Aviatrix Product Suite, various types of cloud security, security controls and any other platforms.
- Participate in the development, testing, and implementation of firewalls and proxy servers
- Verify devices are configured in accordance with DISA Security Technical Implementation Guides (STIGs).
- Product lifecycle management and upgrades to include installation of hotfixes, patches, and any other features to improve product performance.
- Evaluate and recommend firewall solutions for technology refreshes.
- Deploy and sustain new firewall solutions as prescribed by the government.
- Coordinate with Tier III support teams and government customers throughout design, planning, implementation, and sustainment phases.
- Research and provide quotes and documents necessary to renew licenses and equipment maintenance for firewall, proxy and cloud services.
- Maintain all current applicable firewall, proxy appliance and cloud services policies to include DoD. Participate in the development, implementation, and maintenance of a secure and effective means of remote access for employees who are working offsite.
- Develop and deliver briefings to the upper-level management as required on a variety of subjects relating to Enclave Boundary Defense.
- Provide firewall troubleshooting (24x7x365 on-call support).
- Review and resolve automated firewall log issues as to threats or possible compromises.
- Provide daily maintenance and support for all Enterprise Boundary Defense systems including monitoring system and log files.
- Review and resolve automated firewall log issues as to threats or possible compromises.
- Notify appropriate personnel of possible threats or systems vulnerabilities.
- Respond appropriately to reported or identified incidents in accordance with the Incident response plan.
- CSP Security Posture Assessment:Conduct comprehensive security assessments of existing and planned CSP deployments, identifying vulnerabilities and recommending remediation actions aligned with industry best practices and relevant security frameworks (e.g., NIST CSF, CIS and Benchmarks).
- Security Architecture Documentation, Design and Implementation:Document, design, implement, and maintain secure network architectures for CSP environments, including secure connectivity, network segmentation, intrusion detection/prevention systems (IDS/IPS), and data loss prevention (DLP) solutions. Maintaining comprehensive documentation of security controls, configurations, and processes within the CSP environment.
- Cloud Security Operations and Monitoring:Provide continuous security monitoring and incident response capabilities for CSP environments, including log analysis, threat intelligence integration, vulnerability management, and incident response planning and execution.
- Audit, Compliance and Governance:Ensure compliance with relevant security regulations and standards (e.g., FedRAMP, FISMA, NIST) for CSP environments, including documentation, reporting, and audit support. Cooperating fully with authorized Government audits and assessments of the CSP environment, providing timely access to documentation, systems, and personnel. Follow DoD Cloud Computing Security Requirements Guide (SRG) and other applicable DoD issuances and instructions.
- Training and Knowledge Transfer:Provide training and knowledge transfer to Government personnel on best practices for securing CSP environments, covering topics such as cloud security fundamentals, secure configuration, threat detection and response, and incident management.
Required Skills, Qualifications, and Experience:
- Experience:
- Five (5) years relevant experience to include:
- Working knowledge and understanding of CheckPoint firewalls to include versions R80.40 and R81.10 and industry standard network environments to include firewall and security hardware/software. Must have knowledge and understanding of Information Assurance Best Practices.
- In depth knowledge of LAN and WAN operations, understanding of how to use Incident Ticket Tracking systems for inputting incident tickets and creating work orders along with a comprehensive knowledge of DOD and DLA security regulations, guidelines, and policies to include, but not limited to, IA standards.
- Hands-on experience with the installation, configuration, and day-to-day sustainment of network equipment, to include but not limited to firewalls, proxy servers, cloud services and other network appliances.
- Security Clearance:
- Must possess IT-I Critical Sensitive security clearance or have a current National Agency Check with Local Agency Check and Credit Check (NACLC).
- Clearance Required: DoD Secret
- Certifications:
- IAT Level II certification or higher (must have one of the following): CCNA Security, CySA+, GICSP, GSEC, Security+CE, CND, SSCP, CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
- Computing Environment (must have one of the following): CCSA, CCSE or CCSM
- Location:
- Candidates must reside within a commutable distance of one of the following locations in order to work onsite full time: Columbus, OH; Fort Belvoir, VA; or New Cumberland, PA.
Preferred Qualifications:
- One of the following: AWS Cloud Practitioner, Microsoft Certified: Azure Fundamentals, or Comp TIA Cloud+
Work Environment and Physical Demand:
- Must be able to lift up 50 lbs.
Compensation: $90,000+
At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.
- 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
- Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
- 401(k) with Match: We match 3% of your contributions with immediate vesting.
- Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
- Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
- Parental Leave: 15 days of fully paid leave for new parents, because family matters.
- Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving.
- Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
- Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.
At AGE, you'll do work that matters, supported by a company that delivers for its people.
The Patching / SCCM Administrator will provide Tier III IT operations support across the Office of Information Management (OIM) and SC mission systems, with a focus on endpoint management, patching, and compliance. This role is responsible for operating and maintaining Microsoft Endpoint Configuration Manager (SCCM), Intune, and related patching infrastructure, ensuring timely updates, secure baselines, and compliance with DOE directives and federal IT standards. The ideal candidate will have strong expertise in Windows desktop/server patching, automation, and reporting, while supporting hybrid environments and evolving enterprise service delivery models.
Responsibilities:
- Plan, schedule, and deploy Windows OS and application patches across servers and endpoints in accordance with OIM policy.
- Validate patch compliance against secure configuration baselines and DOE directives.
- Perform pre- and post-patch testing, documenting results and mitigating issues.
- Maintain patch deployment records, including maintenance logs, validation history, and compliance reports.
- Collaborate with cybersecurity teams to remediate vulnerabilities identified through patching gaps.
- Administer and maintain Microsoft Endpoint Configuration Manager (SCCM), including collections, deployments, task sequences, and reporting.
- Support Microsoft Intune for mobile device and modern endpoint management.
- Develop and maintain automation scripts (PowerShell, Azure CLI) to streamline patching and endpoint management tasks.
- Manage software distribution, OS imaging, and application packaging for enterprise endpoints.
- Monitor SCCM infrastructure health, including site servers, distribution points, and SQL databases.
- Continuously monitor patch compliance, endpoint health, and SCCM infrastructure performance.
- Generate and deliver compliance reports to leadership and stakeholders.
- Track and report on capacity utilization, resource consumption, and licensing compliance.
- Detect and resolve patching failures, bottlenecks, and outages in line with SLAs.
- Maintain and update the Configuration Management Database (CMDB) with patching and endpoint configuration items.
- Submit all patching changes via the OIM-approved change management system in accordance with the Change Control Review (CCR) process.
- Evaluate proposed changes for technical and cybersecurity risk, ensuring compliance with secure baselines.
- Maintain documentation of patching SOPs, SCCM configurations, and endpoint policies, reviewed quarterly or after major changes.
Minimum Qualifications:
- Bachelor's Degree in Information Technology, Computer Science or a related field or equivalent relevant experience; Master's Degree preferred.
- 7-10 years of experience in information technology, systems administration or other IT related field.
Other Job Specific Skills:
- Demonstrated technical proficiency equivalent to industry-recognized certifications, such as: Microsoft Certified: Endpoint Administrator Associate, Microsoft Certified: Windows Server Hybrid Administrator Associate, CompTIA Security+ or Network+.
- Vendor-specific certifications in endpoint security or patch management platforms.
- Proficiency in PowerShell scripting, SCCM administration, and automation tools.
- Strong knowledge of Windows OS patching, SCCM infrastructure, Intune, and compliance frameworks.
- Ability to support Windows, macOS, and Linux endpoints as required.
- Familiarity with federal IT compliance standards (e.g., FISMA, NIST SP 800-53).
Preferred Skills:
- Experience with hybrid endpoint management (SCCM + Intune).
- Familiarity with vulnerability management tools (e.g., Tenable, Qualys) and integration with patching workflows.
- Strong troubleshooting skills for patch deployment failures, SCCM infrastructure issues, and endpoint compliance gaps.
- Excellent documentation and communication skills for compliance reporting and operational transparency.
- Knowledge of federal government IT best practices and standards.
- Experience with continuous monitoring and incident response in a federal environment.
- Ability to work under federal IT security protocols and procedures.
- Understanding and application of FISMA (Federal Information Security Management Act) requirements.
- Familiarity with NIST (National Institute of Standards and Technology) Special Publications, particularly SP 800-53 (Security and Privacy Controls for Information Systems and Organizations).
- Experience with the RMF process for federal information systems, including system categorization, control selection, implementation, assessment, and continuous monitoring.
- Strong skills in incident detection, response, and recovery, following federal guidelines and protocols.
- Knowledge of cloud security principles and best practices, particularly relating to the security of cloud services used by the federal government (e.g., FedRAMP).
Functional Analyst opportunity with SOC’s client to work onsite at Scott Air Force Base.
Candidates must have an active Secret Clearance to be considered for this role
Responsibilities
- Lead requirements elicitation and analysis with Military Service and DoD Agency representatives using deep knowledge of Traffic Management, Sealift, Air Transportation, and Deployment/Redeployment regulations and policies.
- Develop and maintain use cases, BPMN process models, functional designs, and supporting documentation.
- Support backlog refinement, including development of epics, features, and user stories aligned to validated operational outcomes.
- Facilitate and document Working Integrated Process Teams (WIPTs), Functional Review Boards (FRBs), and Agile Change Control Boards (CCBs).
- Support DOTMLPF-P requirements refinement, alignment, and traceability across stakeholders.
- Coordinate updates and maintain artifacts within Government-provided requirements management tools.
- Produce briefings, reports, and status materials for senior government leadership.
- Serve as a bridge between technical and non-technical stakeholders, ensuring shared understanding and informed decision-making.
Required Qualifications
- Active SECRET clearance.
- Bachelor’s degree or equivalent relevant experience.
- Minimum of five (5) years of experience in requirements analysis and business process reengineering.
- Experience supporting DoD logistics or transportation operations and systems.
- Demonstrated experience with BPMN, use cases, and requirements traceability matrices.
- Experience supporting Agile and/or SAFe delivery environments.
- Strong facilitation, documentation, and stakeholder coordination skills.
- Experience working across technical, functional, financial, and administrative teams.
- Ability to translate complex technical concepts into clear, actionable information for non-technical audiences.
Preferred Qualifications
- Experience supporting or implementing ERP solutions delivered via a SaaS model in a DoD or Federal environment.
- Knowledge of ERP-driven business process reengineering and configuration-based solution design.
- Experience with system integration, data migration, and master data management in ERP environments.
- Familiarity with RMF, cloud security, and FedRAMP considerations for SaaS solutions.
- Experience supporting Agile or SAFe governance for COTS/SaaS implementations.
- SAFe Agilist (SA), SAFe Practitioner (SP), or equivalent Agile certification.
- Familiarity with DOTMLPF-P analysis.
- Experience supporting joint or multi-Service programs.
Employment Prerequisites
The following requirements must be met to be eligible for this position: successful completion of a background investigation and drug urinalysis.
SOC, a Day & Zimmermann company, is an Equal Opportunity Employer, EOE AA M/F/Vet/Disability.
Note: Any pay ranges displayed are estimations, which may have been provided by job boards. Actual pay is determined by an applicant’s experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply.
Summary
Summary/Objective:
At Kyra Solutions, we implement business solutions for government workers with best-of-breed technology platforms. Our goal is to improve the effectiveness and quality of work life for state workers in capitals across the U.S. to help better the lives of citizens they serve. State agencies choose Kyra for our dedicated team of experts who ensure the success of every project through client empathy, expert knowledge, and a dedication to value-based outcomes. As Kyra continues to reach new heights nationally, our in-office and remote team members are growing with it. We believe we must and do put our people first to produce the quality our clients expect and deserve. Kyrians are provided a growth track for long-term career success and continuous professional development. If you are looking to make an impact in your community and create a career you can be proud of, we encourage you to apply!
Title : Project Manager/ Business Analyst (On-site & Full-Time)
Location : Tallahassee, FL || Duration: Full Time
Required Skills and Experience
- Bachelor s degree in Information Systems, Business, or related field (Master s preferred).
- 5+ years of experience managing complex Salesforce or CRM implementation projects.
- 3+ years managing technology projects in public sector or government environments.
- Strong understanding of Salesforce ecosystem (Sales, Service, Experience Cloud, PSS, GovCloud).
- Exceptional communication, documentation, and stakeholder engagement skills.
- Exceptional ability to lead cross-functional, multi-vendor teams under bureaucratic constraints.
- Strong negotiation and facilitation skills to reconcile IT, policy, and operations interests.
Preferred Certifications
- PMP and/or Prince 2 Certification
- Salesforce Certified Administrator or Salesforce Business Analyst Certification
- Salesforce Certified Consultant (Public Sector, Service Cloud, or Experience Cloud)
- Certified ScrumMaster (CSM) or SAFe Agile
- Security+ or equivalent
Roles and Responsibilities
- Lead the end-to-end delivery of Salesforce projects from initiation through deployment and post-go-live support.
- Define project scope, milestones, and deliverables aligned with government timelines and funding cycles.
- Manage project budgets, resource allocations, and risk registers in accordance with PMO or agency standards.
- Implement effective change control and governance to ensure compliance with contracts and SOWs.
- Serve as the primary liaison between government clients, technical teams, and executive sponsors.
- Facilitate stakeholder workshops, requirement sessions, and steering committee meetings.
- Manage implementation of Salesforce Public Sector Solutions (PSS), Experience Cloud, and related modules.
- Ensure compliance with public-sector frameworks including FedRAMP, NIST, CJIS, or StateRAMP.
- Conduct stakeholder interviews, workshops, and process mapping sessions across multiple agencies or departments.
- Elicit, document, and validate functional and non-functional requirements for Salesforce Public Sector Solutions (PSS), Experience Cloud portals, and case management systems.
- Translate complex public-sector policies and procedures into configurable Salesforce features and workflows.
- Develop user stories, acceptance criteria, and business process documentation in tools such as Jira or Confluence.
- Partner with Solution Architects, Developers, and Product Owners to ensure requirements are understood, feasible, and aligned with Salesforce best practices.
- Recommend improvements and assist in backlog grooming for Agile delivery.
- Analyze existing case management, licensing, permitting, or citizen service processes and recommend Salesforce-enabled efficiencies.
- Ensure all documentation and requirements align with government compliance, audit, and reporting standards.
- Collaborate on grant, budget, or legislative reporting requirements integrated within Salesforce.
- Prepare status reports, requirement traceability matrices (RTMs), and process diagrams.
- Maintain detailed documentation for system requirements, process flows, and future enhancements.
- Assist in developing training materials and user guides to support end-user adoption and change management efforts.
- Lead multi-disciplinary teams of Salesforce administrators, developers, analysts, architects, data analysts and partners.
Why Kyra:
Founded in 1997, Kyra Solutions is a national leader in transportation technology and regulatory solutions in government. We specialize in the art and science of digital transformation in government. Our commitment to providing the highest level of service and tailored solutions has supported our consistent double-digit growth for over a decade. We are headquartered in the greater Tampa Bay area with other offices across Florida and an innovation center in Silicon Valley, CA.
Because of our dedication to our employees, we have won a Best Companies to Work for in Florida 2 years in a row by Florida Trend magazine. Kyra has won other numerous awards including the coveted INC magazine s one of America s Fastest Growing Companies several years in a row. Kyra s commitment to our employees, to best practices in project management and business analysis, and to solution development has led to our achievement in becoming the first Project Management Institute certified company in Florida. Our proven successful track record has resulted in several prestigious awards including the State of Florida's Diversity Business of the Year Award. We are proud to be a sponsor for the TaxWatch Productivity Awards and partner to Florida TaxWatch. Visit our website for more information. Equal employment opportunity employer.
Our client, Vercel, is seeking a Director of Legal, Product Foundations.
About Vercel:
Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.
Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.
About the Role:
Vercel is hiring a Director of Legal, Product Foundations, to build the legal foundations that enable our product velocity at scale. The core priority for this role is leading privacy and regulatory matters on the legal team; you will also oversee IP and litigation.
You will report to Vercel's VP of Legal and partner closely with Security, Trust & Safety, and GRC, as well as product, engineering, and other teams.
This role is based in SF, where we have a 3-day/week in-office requirement.
What You Will Do:
- Lead Vercel's privacy program, regulatory strategy and frameworks, IP strategy, litigation, and the legal team's incident response processes
- Translate complex requirements into business-oriented, actionable guidance so product teams can continue to ship fast
- Build scalable programs using policies, playbooks, templates, training, and AI
About You:
- California Bar admission or eligible for Registered In-House Counsel exception, and in good standing.
- 12+ years of legal experience, including meaningful product counseling, privacy, and/or regulatory experience in-house at a high-growth technology company serving enterprise customers
- Strong understanding of AI, cloud services, and general b2b SaaS, PaaS, and IaaS business practices and relevant global regulatory requirements
- Strong judgment and creativity around risk-assessment and mitigation. Able to make decisions with imperfect facts, embracing Vercel's speed and obsession with product innovation
- Deep technical literacy. Comfortable mapping technical architectures, data flows, and controls into legal risk frameworks. Excited to dig deep to understand Vercel's evolving product suite.
- Exceptional communication and advocacy skills, particularly with non-lawyers
- Cooperative approach, willing to take on additional responsibilities where no job is too big or too small
- Experience managing legal teams, building strategic programs, and partnering with senior business and technical leaders.
- Fluency with AI tools
Bonus If You:
- Prior history leading litigation and IP (including familiarity with open source software)
- Experience supporting IPO readiness, M&A integration, and cyber incidents
- Hands-on experience with DMCA, Digital Services Act, HIPAA, FedRAMP, and other regulations and certifications applicable to Vercel
Benefits:
- Competitive compensation package, including equity.
- Inclusive Healthcare Package.
- Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
- Flexible Time Off.
- We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
Vercel has exclusively engaged Kerwin Associates to conduct this search. Any resumes sent directly to Vercel will be forwarded to Kerwin Associates. If you are interested in speaking about or applying for this role, please contact Anne Kerwin Payne () at Kerwin Associates.
This critical role will focus on driving the organization’s adherence to complex regulatory frameworks, with particular emphasis on FedRAMP, CMMC, NIST 800-171, and ISO 27001.
The ideal candidate will bring a wealth of experience in auditing, risk management, and compliance within high-stakes environments, particularly for Government security standards.
Preferably, this position will have a hybrid work schedule of one or two days a week in either our Washington, DC or Chicago, IL office.
Remote applicants may also be considered.
DEPARTMENT: DSS Security and Compliance Technology is integral to NORC’s mission of advancing social science research.
The IT department delivers innovative, high-quality solutions that support both our staff and clients, ensuring the highest standards of security and compliance.
RESPONSIBILITIES: Lead comprehensive internal and external IT compliance audits, ensuring alignment with critical security standards such as FedRAMP, CMMC, NIST 800-171, and ISO 27001.
Execute in-depth risk assessments and security impact analyses of information systems, identifying potential vulnerabilities and proposing mitigation strategies.
Develop, review, and manage key audit documentation, including the creation of corrective action and remediation plans to address identified deficiencies.
Oversee and ensure continuous compliance with contract requirements, with a focus on tracking and reporting the progress of Corrective Action Plans (CAPs).
Collaborate closely with Security Engineers and stakeholders to remediate compliance issues, ensuring alignment with regulations such as FISMA, Section 508, NIST SP 800-53, HITRUST, and HIPAA Security & Privacy standards.
Design, implement, and optimize policies, procedures, and automated processes for compliance in hybrid and multi-tenant infrastructures.
Provide mentorship and strategic guidance to IT teams, translating complex regulatory requirements into actionable technical steps for seamless compliance execution.
Foster strong, collaborative relationships with NORC’s research community and other key stakeholders, facilitating a culture of compliance and security.
REQUIRED SKILLS: Bachelor’s Degree in Management Information Systems, Computer Science, Business Administration, or a related field.
Or equivalent experience in IT security, risk, or compliance may be considered.
Current certifications in IT security compliance, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC).
Minimum of 6+ years of experience in IT security auditing, risk assessment, or compliance, with a primary focus on government security frameworks and contracts.
Proven expertise in auditing IT systems for compliance with security frameworks, including preparing and reviewing System Security Plans (SSPs), Corrective Action Plans (CAPs), and Contingency Plans.
Proficiency in Governance, Risk, and Compliance (GRC) or Information Risk Management (IRM) systems, with a track record of managing compliance across multiple frameworks, including FedRAMP, NIST, and ISO standards.
Deep knowledge of information security protocols across infrastructure layers, including networks, servers, databases, and applications, with hands-on experience in advanced security assessment techniques.
Experience managing compliance in hybrid and multi-tenant infrastructures, with strong familiarity with privacy regulations such as GDPR, CCPA/CPRA, and the HIPAA Privacy Rule.
Extensive experience in the implementation and oversight of frameworks such as FedRAMP, CMMC, NIST 800-171, ISO 27001, and HITRUST.
Qualified applicants must be eligible to work in the U.S.
We regret that we are unable to offer visa sponsorship for this position.
SALARY AND BENEFITS: The pay range for this position is $110,000 – $165,000.
This position is classified as regular.
Regular staff are eligible for NORC’s comprehensive benefits program.
Benefits include, but are not limited to: Generously subsidized health insurance, effective on the first day of employment Dental and vision insurance A defined contribution retirement program, along with a separate voluntary 403(b) retirement program Group life insurance, long-term and short-term disability insurance Benefits that promote work/life balance, including generous paid time off, holidays; paid parental leave, bereavement leave, tuition assistance, and an Employee Assistance Program (EAP).
NORC’s Approach to Equity and Transparency Pay and benefits transparency helps to reduce wage gaps.
As part of our commitment to pay equity and salary transparency, NORC includes a salary range for each job opening along with information about eligible benefit offerings.
At NORC, we take a comprehensive approach to setting salary ranges and reviewing raises and promotions, which is overseen by a formal Salary Review Committee (SRC).
WHAT WE DO: NORC at the University of Chicago is an objective, non-partisan research institution that delivers reliable data and rigorous analysis to guide critical programmatic, business, and policy decisions.
Since 1941, our teams have conducted groundbreaking studies, created and applied innovative methods and tools, and advanced principles of scientific integrity and collaboration.
Today, government, corporate, and nonprofit clients around the world partner with us to transform increasingly complex information into useful knowledge.
WHO WE ARE: For over 80 years, NORC has evolved in many ways, moving the needle with research methods, technical applications and groundbreaking research findings.
But our tradition of excellence, passion for innovation, and commitment to collegiality have remained constant components of who we are as a brand, and who each of us is as a member of the NORC team.
With world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we’re known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale.
EEO STATEMENT: NORC is an equal opportunity employer.
NORC evaluates qualified applicants without regard to race, color, religion, sex, gender, national origin, disability, status as a protected veteran, sexual orientation, and other legally protected characteristics.
#LI-MS1
Remote working/work at home options are available for this role.
This critical role will focus on driving the organization’s adherence to complex regulatory frameworks, with particular emphasis on FedRAMP, CMMC, NIST 800-171, and ISO 27001.
The ideal candidate will bring a wealth of experience in auditing, risk management, and compliance within high-stakes environments, particularly for Government security standards.
Preferably, this position will have a hybrid work schedule of one or two days a week in either our Washington, DC or Chicago, IL office.
Remote applicants may also be considered.
DEPARTMENT: DSS Security and Compliance Technology is integral to NORC’s mission of advancing social science research.
The IT department delivers innovative, high-quality solutions that support both our staff and clients, ensuring the highest standards of security and compliance.
RESPONSIBILITIES: Lead comprehensive internal and external IT compliance audits, ensuring alignment with critical security standards such as FedRAMP, CMMC, NIST 800-171, and ISO 27001.
Execute in-depth risk assessments and security impact analyses of information systems, identifying potential vulnerabilities and proposing mitigation strategies.
Develop, review, and manage key audit documentation, including the creation of corrective action and remediation plans to address identified deficiencies.
Oversee and ensure continuous compliance with contract requirements, with a focus on tracking and reporting the progress of Corrective Action Plans (CAPs).
Collaborate closely with Security Engineers and stakeholders to remediate compliance issues, ensuring alignment with regulations such as FISMA, Section 508, NIST SP 800-53, HITRUST, and HIPAA Security & Privacy standards.
Design, implement, and optimize policies, procedures, and automated processes for compliance in hybrid and multi-tenant infrastructures.
Provide mentorship and strategic guidance to IT teams, translating complex regulatory requirements into actionable technical steps for seamless compliance execution.
Foster strong, collaborative relationships with NORC’s research community and other key stakeholders, facilitating a culture of compliance and security.
REQUIRED SKILLS: Bachelor’s Degree in Management Information Systems, Computer Science, Business Administration, or a related field.
Or equivalent experience in IT security, risk, or compliance may be considered.
Current certifications in IT security compliance, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC).
Minimum of 6+ years of experience in IT security auditing, risk assessment, or compliance, with a primary focus on government security frameworks and contracts.
Proven expertise in auditing IT systems for compliance with security frameworks, including preparing and reviewing System Security Plans (SSPs), Corrective Action Plans (CAPs), and Contingency Plans.
Proficiency in Governance, Risk, and Compliance (GRC) or Information Risk Management (IRM) systems, with a track record of managing compliance across multiple frameworks, including FedRAMP, NIST, and ISO standards.
Deep knowledge of information security protocols across infrastructure layers, including networks, servers, databases, and applications, with hands-on experience in advanced security assessment techniques.
Experience managing compliance in hybrid and multi-tenant infrastructures, with strong familiarity with privacy regulations such as GDPR, CCPA/CPRA, and the HIPAA Privacy Rule.
Extensive experience in the implementation and oversight of frameworks such as FedRAMP, CMMC, NIST 800-171, ISO 27001, and HITRUST.
Qualified applicants must be eligible to work in the U.S.
We regret that we are unable to offer visa sponsorship for this position.
SALARY AND BENEFITS: The pay range for this position is $110,000 – $165,000.
This position is classified as regular.
Regular staff are eligible for NORC’s comprehensive benefits program.
Benefits include, but are not limited to: Generously subsidized health insurance, effective on the first day of employment Dental and vision insurance A defined contribution retirement program, along with a separate voluntary 403(b) retirement program Group life insurance, long-term and short-term disability insurance Benefits that promote work/life balance, including generous paid time off, holidays; paid parental leave, bereavement leave, tuition assistance, and an Employee Assistance Program (EAP).
NORC’s Approach to Equity and Transparency Pay and benefits transparency helps to reduce wage gaps.
As part of our commitment to pay equity and salary transparency, NORC includes a salary range for each job opening along with information about eligible benefit offerings.
At NORC, we take a comprehensive approach to setting salary ranges and reviewing raises and promotions, which is overseen by a formal Salary Review Committee (SRC).
WHAT WE DO: NORC at the University of Chicago is an objective, non-partisan research institution that delivers reliable data and rigorous analysis to guide critical programmatic, business, and policy decisions.
Since 1941, our teams have conducted groundbreaking studies, created and applied innovative methods and tools, and advanced principles of scientific integrity and collaboration.
Today, government, corporate, and nonprofit clients around the world partner with us to transform increasingly complex information into useful knowledge.
WHO WE ARE: For over 80 years, NORC has evolved in many ways, moving the needle with research methods, technical applications and groundbreaking research findings.
But our tradition of excellence, passion for innovation, and commitment to collegiality have remained constant components of who we are as a brand, and who each of us is as a member of the NORC team.
With world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we’re known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale.
EEO STATEMENT: NORC is an equal opportunity employer.
NORC evaluates qualified applicants without regard to race, color, religion, sex, gender, national origin, disability, status as a protected veteran, sexual orientation, and other legally protected characteristics.
#LI-MS1
Remote working/work at home options are available for this role.
Salary: $90,000
- $150,000 per year A bit about us: SaaS startup in GRC/FedRAMP cybersecurity! Why join us? Competitive salary with equity options 100% employer-paid medical, dental, and vision At least 20 days of PTO Fully paid parental leave Flexible work schedule and hybrid work structure Ongoing training and professional development support Collaborative, growth-oriented company culture Job Details You will act as the bridge between technical depth and business outcomes—helping customers understand how our client can accelerate their compliance journey across frameworks like FedRAMP, GovRAMP, TX-RAMP, SOC 2, and CMMC.
Qualifications 3+ years in a technical pre-sales, solutions engineering, or technical consulting role at a SaaS company, preferably in cybersecurity, compliance, or risk management.
Strong understanding of GRC frameworks (SOC 2, ISO 27001, FedRAMP, FISMA, CMMC, NIST 800-53/171, etc.) and how they map to modern cloud environments (AWS, Azure, GCP).
Ability to design and present solutions that meet technical and business requirements across multiple stakeholders.
Excellent communication and presentation skills; able to explain complex security or compliance topics in clear, engaging terms.
Experience integrating with security tooling (SIEM, vulnerability scanners, identity management, endpoint protection, etc.) is a plus.
Proficiency in tools such as HubSpot, Slack, JIRA, Zendesk, and diagramming tools (Lucidchart, Miro).
Self-starter with a collaborative mindset and passion for helping customers succeed.
Technical background (Computer Science, Information Systems, or related field) preferred; certifications such as CISSP, CISA, or CCSK are a plus.
Interested in hearing more? Easy Apply now by clicking the "Apply Now" button.
Jobot is an Equal Opportunity Employer.
We provide an inclusive work environment that celebrates diversity and all qualified candidates receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, age (40 and over), disability, military status, genetic information or any other basis protected by applicable federal, state, or local laws.
Jobot also prohibits harassment of applicants or employees based on any of these protected categories.
It is Jobot’s policy to comply with all applicable federal, state and local laws respecting consideration of unemployment status in making hiring decisions.
Sometimes Jobot is required to perform background checks with your authorization.
Jobot will consider qualified candidates with criminal histories in a manner consistent with any applicable federal, state, or local law regarding criminal backgrounds, including but not limited to the Los Angeles Fair Chance Initiative for Hiring and the San Francisco Fair Chance Ordinance.
Information collected and processed as part of your Jobot candidate profile, and any job applications, resumes, or other information you choose to submit is subject to Jobot's Privacy Policy, as well as the Jobot California Worker Privacy Notice and Jobot Notice Regarding Automated Employment Decision Tools which are available at /legal.
By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Jobot, and/or its agents and contracted partners.
Frequency varies for text messages.
Message and data rates may apply.
Carriers are not liable for delayed or undelivered messages.
You can reply STOP to cancel and HELP for help.
You can access our privacy policy here: /privacy-policy
Salary: $200,000
- $260,000 per year A bit about us: We are seeking a dynamic and innovative Director of Site Reliability Engineering to join our growing team.
This role is pivotal in maintaining the stability and efficiency of our cutting-edge technology services, ensuring that our systems are always online and performant.
The successful candidate will be responsible for leading a talented team of engineers, developing and implementing site reliability best practices, and driving continuous improvement initiatives.
This is an exciting opportunity to be at the forefront of technology, working in a fast-paced, innovative environment where your work will have a direct impact on our business and customers.
Why join us? Competitive Base Salary + Stock options Company paid health plan for employees Flexible Hours Very generous PTO Dental and Vision, FSA, HSA Small team, autonomy Many more great perks! Job Details We are seeking a dynamic and innovative Director of Site Reliability Engineering to join our growing team.
This role is pivotal in maintaining the stability and efficiency of our cutting-edge technology services, ensuring that our systems are always online and performant.
The successful candidate will be responsible for leading a talented team of engineers, developing and implementing site reliability best practices, and driving continuous improvement initiatives.
This is an exciting opportunity to be at the forefront of technology, working in a fast-paced, innovative environment where your work will have a direct impact on our business and customers.
Responsibilities: 1.
Lead, mentor, and manage a high-performing team of Site Reliability Engineers.
2.
Develop and implement best practices for system reliability, scalability, operability, and performance.
3.
Collaborate with engineering teams to define service level objectives, ensure we are exceeding them, and implement strategies to improve upon them.
4.
Drive the design and deployment of our multi-region architectures and on-prem deployments.
5.
Utilize your expertise in K8 and CloudFormation to automate and innovate.
6.
Oversee compliance with frameworks such as FedRAMP and SOC 2.
7.
Develop a deep understanding of our AI/ML Infrastructure to ensure optimal performance and reliability.
8.
Work closely with other teams to identify and correct bottlenecks in the delivery process.
9.
Spearhead incident management, ensuring swift resolution, comprehensive post-mortem investigations, and effective preventative measures.
Qualifications: 1.
Bachelor’s degree in Computer Science, Engineering, or related field.
2.
Minimum of 5 years of experience in Site Reliability Engineering leadership & 10+ years of SRE/Infrastructure/DevOps experience 3.
Proven leadership experience managing high-performing engineering teams.
4.
Extensive experience with K8, CloudFormation, and multi-region architectures.
5.
In-depth understanding of compliance frameworks such as FedRAMP and SOC 2.
6.
Prior experience in a startup environment is highly desirable.
7.
Proficiency in AI/ML Infrastructure and on-prem deployments.
8.
Exceptional problem-solving skills and attention to detail.
9.
Excellent communication and interpersonal skills.
10.
Proven ability to thrive in a fast-paced, dynamic environment.
Join us in this exciting role where you can make a significant impact.
We are committed to fostering a culture of innovation, teamwork, and professional growth.
If you are a driven, results-oriented leader with a passion for technology and a knack for problem-solving, we would love to hear from you.
Interested in hearing more? Easy Apply now by clicking the "Apply Now" button.
Jobot is an Equal Opportunity Employer.
We provide an inclusive work environment that celebrates diversity and all qualified candidates receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, age (40 and over), disability, military status, genetic information or any other basis protected by applicable federal, state, or local laws.
Jobot also prohibits harassment of applicants or employees based on any of these protected categories.
It is Jobot’s policy to comply with all applicable federal, state and local laws respecting consideration of unemployment status in making hiring decisions.
Sometimes Jobot is required to perform background checks with your authorization.
Jobot will consider qualified candidates with criminal histories in a manner consistent with any applicable federal, state, or local law regarding criminal backgrounds, including but not limited to the Los Angeles Fair Chance Initiative for Hiring and the San Francisco Fair Chance Ordinance.
Information collected and processed as part of your Jobot candidate profile, and any job applications, resumes, or other information you choose to submit is subject to Jobot's Privacy Policy, as well as the Jobot California Worker Privacy Notice and Jobot Notice Regarding Automated Employment Decision Tools which are available at /legal.
By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Jobot, and/or its agents and contracted partners.
Frequency varies for text messages.
Message and data rates may apply.
Carriers are not liable for delayed or undelivered messages.
You can reply STOP to cancel and HELP for help.
You can access our privacy policy here: /privacy-policy